3 ms·
Part of the problem is that privacy, at least in this context, is framed as a "debate" at all, rather than as a matter for individual choice. Some people would
by discostrings 13y ago
Part of the problem is that privacy, at least in this context, is framed as a "debate" at all, rather than as a matter for individual choice.
Some people would gladly share medical information for the greater good if asked. You'd have to pry it from the cold, dead hands of others. The problem is that we currently don't separate those who would like to provide their information from those who would like to refuse because we're greedy for as much information as we can get, or we don't trust people to make the "right" decision.
A system that worked well and that accomodated both views would be one that really respected a user's choice--one that could handle data in a centralized or individual fashion, accordingly. Data that was willingly given could be used under the terms of the agreement without risk of angering people who don't want their data to be analyzed. It would ultimately provide the same benefits while respecting individuals and not creating controversy.
In the medical records situation, you'd have a group of people at one end that would be quite pleased to contribute their information, a group at the other end that would immediately decline, and quite a few people in the middle who would likely fall somewhat evenly to either side. Sure, some people would probably be fear-mongered out of sharing, but I imagine there'd be a lot less of that going on if people knew they could actually make a meaningful individual choice for privacy if they chose to do so. When opt-outs are buried, hidden, and it's not clear that they actually work, skepticism and fear grow. In a system that doesn't try to railroad people to sacrifice their privacy--a system that actually respects the individual's choice--fear would be reduced.
The only way to cast questions around this type of privacy as "a debate" involves changing the issue to compelled sharing of personal information. In a debate over forced participation, I think it's pretty easy to see why thoughts start to drift towards totalitarian concerns.
I think a system that offered real choice for each individual may drastically reduce the current problems from both perspectives, at the price of some engineering overhead.
- moultano 13y agoA few points. There isn't any coercion going on with any of the things we're talking about. Every technology product has at least the choice to not use it. It's quite difficult to ask meaningful questions about what users are comfortable with, get meaningful answers, and then figure out how the answer they've already given applies to a grey area situation where the cost of getting it wrong is a lawsuit. It becomes no longer sufficient to treat the data with respect and only use it for beneficial and privacy respecting purposes. You now have to constrain it by another set of rules whose relationship to what's actually happening can be unclear and arbitrary. Some products work without storing any data. Most don't. For those that require user data to fulfill their basic function, the engineering cost of exempting certain data from certain systems can be much higher. One programmer screwing up becomes a lawsuit. This is essentially the situation with HIPAA. Everyone is too worried about liability to do anything innovative, so that sector doesn't improve. If someone is actually harmed by something a company does with user data, then it's entirely appropriate to stop patronizing that company, or to claim damages through all the normal routes. The presumption of not trusting anyone with data in advance of any actual harm is what I object to. Data can do real and permanent good in the world, and some companies are worth trusting (particularly since all of their incentives are to remain trustworthy if they want to continue to exist.)
- Silhouette 13y agoThere isn't any coercion going on with any of the things we're talking about. Every technology product has at least the choice to not use it. But that's exactly the problem: many of the modern technologies that pose potential risks to privacy don't in practice provide an opt-out for the people whose privacy they might infringe. Sometimes, you do have a choice. However, if you don't know about it or understand the implications, you can't make an informed decision. Sometimes you don't get any meaningful choice, for example if governments decide it's OK to share sensitive healthcare information now. Strictly speaking you do have a choice, but that choice is never to visit a doctor or hospital. Try contrasting the dangers from a significant reduction in public trust in the integrity and ethics of the entire medical profession with the hypothetical future benefits of analysing aggregate healthcare data, and let me know which one really seems like the bigger risk. Sometimes you don't get any choice in practice because your data is collected incidentally. When you were in the background of someone's personal holiday snap, that didn't really matter. When you're in the background of a CCTV image, which is centrally recorded and subject to future data mining operations, it matters more. When you're in the background of numerous CCTV images just because you left your home, which are subject to geotagging, facial recognition, gait analysis, covert audio recording, correlation with other databases such as mobile phone history, ANPR scans and purchase history, permanent archival and any additional data mining techniques that anyone who gets hold of the data might find later... Well, now you're in the plot of a sci-fi short story that doesn't end well. Except that of course, it's not a story any more. Insurers already bump premiums based on profiling, but that profiling is notoriously inaccurate. Lenders already check credit records, which again are notoriously inaccurate. Employers already not only Google job applicants but in some cases also ask for personal log-in credentials to read through their social networking history. Governments already sell personal data held for legitimate public interest reasons to private parties, and even in seemingly simple cases like the government's vehicle licensing authority in the UK providing details of the registered owner of a car with given plates, this has been widely abused. Where these things have been curtailed -- which doesn't happen nearly as often as it should -- it has mostly been because primary legislation was passed or the rules for government's own departments were updated to cover specific cases, and only after so many people suffered from the intrusion that it became a politically significant issue. To be clear, I don't object to the idea that there are potentially great benefits to be had from data mining, including in sensitive cases like public health data. But I think you are almost completely ignoring the accompanying risks, despite a seemingly endless stream of failures resulting in serious adverse consequences for individuals whose privacy wasn't adequately protected. We need the rest of how society works to catch up with the capabilities of modern technology before we can reap the benefits without paying too high a price.